EdgeConnect SD-WAN Orchestrator instances prior to the...
High severity
Unreviewed
Published
Aug 22, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Aug 22, 2023
Published to the GitHub Advisory Database
Aug 22, 2023
Last updated
Apr 4, 2024
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator
host.
References